SCADA / ICS
Industrial control systems (ICS) and SCADA operate physical infrastructure: energy, water, manufacturing, transport. Their security inverts IT’s priorities —here availability and physical safety come first— and a failure can have real-world consequences, not just data ones.
Components and architecture
Section titled “Components and architecture”PLC Programmable Logic Controller: runs the control logic of the physical processRTU Remote Terminal Unit: telemetry/control in a remote fieldHMI Human-Machine Interface: the operator's panelSCADA supervision and data acquisition (central)DCS Distributed Control System (plants)Historian time-series database of the processThe Purdue model (segmentation)
Section titled “The Purdue model (segmentation)”Level 5/4 corporate IT / ERPLevel 3.5 industrial DMZ (IT/OT separation zone) <- key control pointLevel 3 plant operations (historian, engineering)Level 2 supervision (SCADA/HMI)Level 1 control (PLC/RTU)Level 0 physical process (sensors/actuators)# IT/OT segmentation at the industrial DMZ is the main structural defenseIT vs OT (inverted priorities)
Section titled “IT vs OT (inverted priorities)”IT C-I-A: Confidentiality firstOT A-I-C (+ SAFETY): Availability and physical safety first# you can't "reboot to patch" a turbine; maintenance windows are rare# equipment decades old, protocols without authentication, can't be touched lightlyThreats and defense
Section titled “Threats and defense”Threats access from IT (pivot), social engineering, USB, vendor remote access, PLC logic tampering, ransomware jumping to OTDefense Purdue segmentation + industrial DMZ, data diodes (unidirectional), PASSIVE monitoring (don't actively scan a fragile PLC), allowlisting, controlled remote access (jump host + MFA), vendor managementTools and frameworks
Section titled “Tools and frameworks”MITRE ATT&CK for ICS TTPs specific to industrial environmentsOT monitoring Nozomi, Claroty, Dragos (passive, by protocol)Standards IEC 62443 (the OT standard), NIST SP 800-82, NERC CIP (energy)# NEVER scan/exploit a production ICS without a lab or an authorized windowBlue Team / operation
Section titled “Blue Team / operation”- Segmenting IT/OT (Purdue + industrial DMZ) is the #1 structural defense; no flat network.
- Passive per-protocol monitoring (Nozomi/Claroty/Dragos): an active scan can take a PLC down.
- Controlled vendor remote access (jump host + MFA + recording); manage the supply chain.
- Align with IEC 62443/NIST 800-82; prioritize safety and availability over confidentiality.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- Stuxnet (2010): manipulated Siemens PLCs to damage Iranian centrifuges; reached an air-gapped network via USB.
- Industroyer/CrashOverride (2016) and Industroyer2 (2022): malware designed for power outages in Ukraine.
- TRITON/TRISIS (2017): attacked a plant’s safety systems (SIS), risking lives.
Testing checklist
Section titled “Testing checklist”- OT asset inventory (PLC/RTU/HMI/SCADA) and Purdue architecture
- IT/OT segmentation verified (industrial DMZ, no flat network)
- Passive per-protocol monitoring deployed
- Controlled vendor remote access (jump host + MFA)
- Tests ONLY in a lab/authorized window (never active scanning in prod)
- Map to MITRE ATT&CK for ICS
- IEC 62443 / NIST 800-82 / NERC CIP compliance per sector